Privacy Policy
Last updated: 26 July 2026
This policy explains what personal data Nerela processes, why, and what rights you have — whether you're a professional with a Nerela account or a patient of a professional who uses Nerela. It's an important document: we process health data, a special category of data under the GDPR (Article 9).
1. Who is the data controller
For your account data (if you're a professional or clinic with a Nerela account — name, email, billing details for your subscription), the data controller is LAGASTROEMIA VENTURES OÜ, with its registered office at Sakala tn 7-2, Kesklinna linnaosa, 10141 Tallinn, Estonia, VAT identification number EE102418024. You can contact us about any data protection matter at ola@nerela.eu.
For the data on patients that a professional enters into the App (patient records, session notes, appointments), the data controller is the professional or clinic themselves — they decide what data to collect and why. Nerela acts here as a processor, handling that data only to provide the service and in line with the professional's instructions, never for our own purposes.
2. What data we process
- Professional account data: name, email, phone number, account type (independent/clinic), preferred language.
- Subscription billing data: tax ID, billing address, IBAN (for your own Nerela plan).
- Patient data entered by the professional: name, contact details (email/phone), address, appointment data, and — the most sensitive category — clinical session notes.
- Minimal technical data: server access and error logs, scrubbed as described in section 9.
3. Health data: legal basis and special care
Session notes and any clinical information are "special category data" under Article 9 of the GDPR. The professional (as controller in relation to their patient) must ensure there's a valid legal basis — typically the patient's explicit consent, or the necessity of their own therapeutic care (Article 9(2)(a) or (h)).
On our side, we protect that data with technical isolation per professional (Row Level Security in Supabase — each professional can only access their own patients at database level) and with the scrubbing policy in our error monitoring described in section 9.
4. Purposes and legal basis for processing
- Providing the service (calendar, records, notes, invoicing, online booking) — performance of our contract with you.
- Processing your subscription and billing — performance of the contract and compliance with legal tax obligations.
- Sending appointment reminders by email/WhatsApp to patients, at the professional's request — performance of the contract between the professional and the patient, through Nerela as processor.
- Security and error detection — legitimate interest in keeping the service running reliably and securely, with personal-data scrubbing (section 9).
5. How long we keep data
While your account is active, we keep the data needed to provide the service. Once you cancel, we delete or anonymise it within a reasonable period, except where there's a legal obligation to keep it longer (for example, tax documentation for your subscription).
Your patients' clinical records have their own retention periods, set by law and by your professional body's rules. As the controller for that data, you're the one who has to meet those retention periods: if you need to keep information beyond the life of your account, talk to us before cancelling (ola@nerela.eu).
6. Who we share data with (subprocessors)
We don't sell data to anyone. We only share data with the providers we need to operate the service, each with their own data protection commitments — see the table at the end of this page.
7. International transfers
Your clinical data — patients, appointments and session notes — is stored and processed within the European Economic Area: Supabase (database, authentication and file storage) is hosted in the EU Paris region, and Vercel, Resend and Twilio all process data within the EU/EEA for this service, under their respective contractual data protection commitments.
There are, in fact, two transfers to the United States, and we'd rather say so clearly than claim there are none. The first is Stripe, which charges your subscription and, if you turn it on, your patients' card payments. The second only happens if you enable the Virtual Secretary: the AI model that drafts WhatsApp replies needs to read the messages in that conversation. Both are covered by the Standard Contractual Clauses approved by the European Commission. Neither one touches your session notes.
If you don't enable the Virtual Secretary, the only transfer outside the EEA is for billing your own subscription.
8. Your rights
If you're a professional with a Nerela account, or a patient of a professional who uses it, you have the right to access, rectify, erase, restrict the processing of, object to, and port your personal data. If you're a patient, your request should normally be directed to your professional first (the controller for your clinical data); we provide technical support for that request.
To exercise these rights directly over your professional account data, write to ola@nerela.eu. The App doesn't yet have a self-service way to export or delete data — this is a known item still to be built; until then, we handle each request manually by email.
9. Security and error monitoring
Data in transit is always encrypted (HTTPS/TLS). Isolation between professionals is enforced at database level (Row Level Security in Supabase), not just in the application.
If we enable Sentry (error monitoring), it's configured with a strict privacy policy: we don't send request bodies, query parameters, session cookies, or session-note content. We don't use session recording ("session replay") or any visual screen capture. Error messages pass through a filter that automatically tries to strip out emails, phone numbers and tax ID numbers before they leave our server.
10. Minors
Nerela is a tool for professionals, not for direct use by patients who are minors. Data on patients who are minors may be processed by the professional responsible for their care, under the same legal basis that applies to the therapeutic relationship.
11. Changes to this policy
We may update this policy to reflect changes to the service or to applicable law. Material changes are communicated by email or through a notice in the App.
12. Supervisory authority
You have the right to lodge a complaint with the competent supervisory authority — in Portugal, the Comissão Nacional de Proteção de Dados (CNPD); in Spain, the Agencia Española de Protección de Datos (AEPD) — without prejudice to any other administrative or judicial remedy.
13. Contact
For any question about this policy or about how we process your data, write to ola@nerela.eu. You'll be writing to the same company named in section 1.
| Provider | What for | Where data is processed |
|---|---|---|
| Supabase | Database, authentication and file storage | EU (Paris, France) |
| Vercel | Application hosting | EU (region configured for EU requests) |
| Resend | Sending transactional emails (invoices, appointment reminders) | EU |
| Twilio | Sending appointment reminders via WhatsApp | EU (depending on account configuration) |
| Sentry | Error monitoring — only active if NEXT_PUBLIC_SENTRY_DSN is configured; it currently isn't | Depends on the Sentry project region chosen (to be confirmed once the project is created) |
| Stripe | Charging your Nerela subscription and, if you enable it, card payments from your patients (Stripe Connect) | Ireland (Stripe Payments Europe), with transfers to the United States under the European Commission's Standard Contractual Clauses |
| Anthropic | Only if you enable the Virtual Secretary: the AI model that drafts WhatsApp replies reads the conversation's messages in order to respond. Data isn't used to train models. | United States, under the European Commission's Standard Contractual Clauses |